> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Frequently Asked Questions

> Learn answers to frequently asked questions. 

<Accordion title="How can I request additional permissions for my role?">
  To request additional permissions, reach out to your administrator or the designated role manager. They can assess your request, considering the principle of least privilege, and make necessary adjustments if required.
</Accordion>

<Accordion title="Can I have multiple roles assigned to my account?">
  No, each account is assigned a single role to maintain clarity and adhere to the principle of least privilege. If your responsibilities change, contact the administrator to reassess and adjust your role accordingly.
</Accordion>

<Accordion title="What should I do if I suspect unauthorized access?">
  If you suspect unauthorized access or notice any unusual activity, immediately report it to your administrator. They will investigate the issue and take appropriate measures to secure the system. Additionally, change your password immediately and ensure that multi-factor authentication (MFA) is enabled.
</Accordion>

<Accordion title="How often should I change my password?">
  It is recommended to change your password periodically and immediately if you suspect it has been compromised. Avoid reusing previous passwords and use a password manager to generate and store secure passwords.
</Accordion>

<Accordion title="Are role changes effective immediately?">
  Yes, role changes take effect immediately upon assignment. However, it's recommended to log out and log back in to ensure the updated roles and permissions are applied consistently.
</Accordion>

<Accordion title="How often should roles and permissions be audited?">
  Roles and permissions should be audited regularly, at least quarterly, or whenever there are organizational changes. Regular audits help ensure that access levels align with current business requirements and reduce security risks.
</Accordion>

<Accordion title="Can I customize roles based on specific business needs?">
  No, the roles are predefined to maintain consistency and security. If you have specific access requirements, discuss them with your administrator, and they can assess whether adjustments are necessary within the existing role structure.
</Accordion>

<Accordion title="Why am I getting 405 Not Allowed when accessing the portal via SSO (for example, Okta)?">
  There is a known limitation with our portal which prevents direct connection from your SSO portal (for example, Okta) to our portal. To access the portal with your SSO login, you need to access via the direct portal URL instead (for example, `https://yourcompany.payrails.io/`).
</Accordion>


## Related topics

- [Frequently Asked Questions](/docs/token-vault/frequently-asked-questions.md)
- [User Management](/docs/account-setup/user-management/index.md)
- [Token Migration](/docs/token-vault/token-migration/index.md)
